Skip to content
    Back to Regulatory Radar
    CriticalFramework UpdateFebruary 26, 2024

    NIST Cybersecurity Framework 2.0 Released

    NIST released version 2.0 of the Cybersecurity Framework, the first major revision since the framework's original publication in 2014. CSF 2.0 introduces a sixth core function, Govern, which elevates cybersecurity governance, risk management strategy, and supply chain risk management to a top-level concern alongside Identify, Protect, Detect, Respond, and Recover. The update also expands the framework's applicability beyond critical infrastructure to all organizations, adds extensive implementation examples, and introduces Community Profiles for sector-specific guidance.

    NIST CSFSaaSHealthcareFinTechDefense

    Key Analytics

    February 26, 2024
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    The addition of the Govern function signals that cybersecurity is now explicitly a board-level and executive leadership responsibility, not just a technical concern. Organizations using CSF 1.1 for compliance mapping, risk assessments, or regulatory reporting must update their programs to incorporate the new function and revised category/subcategory structure. The expanded scope beyond critical infrastructure means CSF 2.0 will be referenced in an even broader range of regulatory frameworks, contractual requirements, and insurance underwriting criteria.

    Recommended Actions

    • Map existing CSF 1.1 profiles and assessments to the 2.0 structure, with particular attention to the new Govern function categories (GV.OC, GV.RM, GV.RR, GV.SC)
    • Brief executive leadership and the board on the Govern function's emphasis on cybersecurity governance as an organizational leadership responsibility
    • Review and update supply chain risk management practices to align with the elevated GV.SC (Supply Chain Risk Management) categories in the Govern function

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Moderate75-150 hours
    Key Workstreams
    • Remapping of existing CSF 1.1 profiles and assessments to the 2.0 category structure
    • Govern function gap closure across GV.OC, GV.RM, GV.RR, and GV.SC
    • Supply chain risk management practice updates to the elevated GV.SC expectations

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 75-150 hours
    Start cold under pressureSignificant · 180-400 hours

    Roughly 105 to 250 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events